←back to thread

482 points sanqui | 9 comments | | HN request time: 2.376s | source | bottom
1. 0xbadcafebee ◴[] No.42292379[source]
Lol. "This is pretty bad. Someone circunvented the ban on emitting public certificates but also disrespected Google's CAA rules. Hope this CA gets banned on Microsoft OSes for good."

Yeah, this is after the certificate was issued, and my guess, used.

Also, has anyone tried to look up CT logs lately? I tried. Can get maybe a single FQDN if you look, but trying to do wildcards or name-alikes, nothing worked. Most of the CT searching websites were straight up broken. Clearly nobody is actually looking at CT logs.

CAs are a joke. There's a dozen different ways to exploit them, they are exploited, and we only find out after the fact, if it's a famous enough domain.

We could fix it but nobody gives a shit. Just apathy and BAU.

replies(5): >>42292471 #>>42292537 #>>42292577 #>>42292621 #>>42292889 #
2. AceJohnny2 ◴[] No.42292471[source]
> We could fix it but nobody gives a shit. Just apathy and BAU.

We really can't fix it. You try and coordinate updates across all major (and most minor, and outdated) OSs, and websites around the world, amateur & professional, from the mom-and-pop store who don't understand any of this, to the big bank that'll take 3 years of procedure.

I have friends who work in the CA field (on the OS side). The level of alcoholism and turnover in the field is... higher than average.

replies(2): >>42292576 #>>42292585 #
3. numbsafari ◴[] No.42292537[source]
Wildcards work on crt.sh:

https://crt.sh/?q=%25.ycombinator.com

replies(1): >>42298563 #
4. doubled112 ◴[] No.42292576[source]
Relative to all professions or relative to just IT/tech?
5. syncsynchalt ◴[] No.42292577[source]
crt.sh gives you direct access to their postgres database, if you find the capabilities of their site lacking.
6. ◴[] No.42292585[source]
7. thayne ◴[] No.42292621[source]
How would you fix it?
8. aaomidi ◴[] No.42292889[source]
Give me a grant of a few million a year and we could do significant improvements here :P
9. numbsafari ◴[] No.42298563[source]
Just wanting to add to my own comment...

crt.sh allows you to subscribe to an RSS feed for wildcard searches. We map those into a slack channel for infrastructure advisory alerts. You can also setup more aggressive alerts if something shows up unexpectedly.

It's an incredibly handy service.